Identify Compute VMs with Secure Boot Disabled

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Identifies Google Compute Engine VM instances reported by Security Command Center with Secure Boot disabled (COMPUTE_SECURE_BOOT_DISABLED findings).

Attribute Value
Type Hunting Query
Solution Google Cloud Platform Security Command Center
ID d87bb737-2f4e-4261-b863-23c8a8999693
Tactics ResourceDevelopment, DefenseEvasion
Techniques T1608, T1562.001
Required Connectors GoogleSCCDefinition
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
GoogleCloudSCC ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Google Cloud Platform Security Command Center